Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE 42.2 Important: GraphicsMagick Update for Major Issues

opensuse
Calendar Grey December 8, 2016
Dist Opensuse Esm H88
A security patch for ImageMagick resolves 28 vulnerabilities to improve robustness and safety on Ubuntu platforms.
An update that fixes 31 vulnerabilities is now available

Description

This update for GraphicsMagick fixes the following issues:

- a possible shell execution attack was fixed. if the first character of

an input filename for 'convert' was a '|' then the remainder of the

filename was passed to the shell (CVE-2016-5118, boo#982178)

- Maliciously crafted pnm files could crash GraphicsMagick (CVE-2014-9805,

[boo#983752])

- Prevent overflow in rle files (CVE-2014-9846, boo#983521)

- Fix a double free in pdb coder (CVE-2014-9807, boo#983794)

- Fix a possible crash due to corrupted xwd images (CVE-2014-9809,

boo#983799)

- Fix a possible crash due to corrupted wpg images (CVE-2014-9815,

boo#984372)

- Fix a heap buffer overflow in pdb file handling (CVE-2014-9817,

boo#984400)

- Fix a heap overflow in xpm files (CVE-2014-9820, boo#984150)

- Fix a heap overflow in pict files (CVE-2014-9834, boo#984436)

- Fix a heap overflow in wpf files (CVE-2014-9835, CVE-2014-9831,

boo#984145, boo#984375)

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2016-1430=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (i586 x86_64):

GraphicsMagick-1.3.25-3.1

GraphicsMagick-debuginfo-1.3.25-3.1

GraphicsMagick-debugsource-1.3.25-3.1

GraphicsMagick-devel-1.3.25-3.1

libGraphicsMagick++-Q16-12-1.3.25-3.1

libGraphicsMagick++-Q16-12-debuginfo-1.3.25-3.1

libGraphicsMagick++-devel-1.3.25-3.1

libGraphicsMagick-Q16-3-1.3.25-3.1

libGraphicsMagick-Q16-3-debuginfo-1.3.25-3.1

libGraphicsMagick3-config-1.3.25-3.1

libGraphicsMagickWand-Q16-2-1.3.25-3.1

libGraphicsMagickWand-Q16-2-debuginfo-1.3.25-3.1

perl-GraphicsMagick-1.3.25-3.1

perl-GraphicsMagick-debuginfo-1.3.25-3.1

References

https://www.suse.com/security/cve/CVE-2014-9805.html

https://www.suse.com/security/cve/CVE-2014-9807.html

https://www.suse.com/security/cve/CVE-2014-9809.html

https://www.suse.com/security/cve/CVE-2014-9815.html

https://www.suse.com/security/cve/CVE-2014-9817.html

https://www.suse.com/security/cve/CVE-2014-9820.html

https://www.suse.com/security/cve/CVE-2014-9831.html

https://www.suse.com/security/cve/CVE-2014-9834.html

https://www.suse.com/security/cve/CVE-2014-9835.html

https://www.suse.com/security/cve/CVE-2014-9837.html

https://www.suse.com/security/cve/CVE-2014-9845.html

https://www.suse.com/security/cve/CVE-2014-9846.html

https://www.suse.com/security/cve/CVE-2014-9853.html

https://www.suse.com/security/cve/CVE-2016-5118.html

https://www.suse.com/security/cve/CVE-2016-6823.html

https://www.suse.com/security/cve/CVE-2016-7101.html

https://www.suse.com/security/cve/CVE-2016-7515.html

https://www.suse.com/security/cve/CVE-2016-7522.html

https://www.suse.com/security/cve/CVE-2016-7528.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:3060-1
Rating: important
Affected Products: openSUSE Leap 42.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here